- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi! I have an strange issue: previosly working FTP sessions have stopped working on our R81.10 firewall. FTP control session on port 21 is established but the data session is not established when acceleration is enabled. If I disable acceleration (fwaccel off), then the ftp data session is established without any issue. Only FTP flows with destination NAT have this issue: FTPs to the same ftp server but without destination NAT doesn't have this issue.
I am aware of the several types of FTP services available, I have tried using all the relevant types one by one (including ftp-pasv) but to no avail.
No drop is seen on the logs and neither with "fw ctl zdebug drop".
I have not found any change on the audit logs that could give a hint about what have caused this change on the behaviour of the firewall, maybe it is the ftp server the one that has been modified but I have no way to confirm that. I have rebooted the devices just in case but it didn't fix the issue.
Hello, TAC found the cause of the issue: if you mark the QoS checkbox on the interface but only on Inbound (not in Outbound) then the FTP data connections are silently dropped.
If "fwaccel off" solves an issue, then TAC has to be involved: https://help.checkpoint.com
Did you upgrade to a JHF recently? (Version/JHF info is useful)
Hi, this is R81.10 with JHF 83, it was installed almost one year ago, we have involved TAC.
Agree with PhoneBoy TAC should be involved, in the meantime as a workaround you can force the problematic FTP traffic F2F/slowpath and avoid any acceleration with the procedure detailed here: sk104468: How to exclude traffic from SecureXL
Hi, I already tried sk104468, adding all the involved IPs to the f2f_addresses section but to no avail... I will recheck it again because I still see the connections on the fwaccel conns table after configuring it.
I have found that some changes on the QoS blade were performed the day the issue started and have seen that they could be some issues with acceleration if QoS policy was created for R77. This is R81.10 JHF 83 but I am sure this policy has been running since R77 and upgraded to the current R81.10... I will try to disable QoS and check if the issue is still there. We have involved TAC.
"If you have a QoS policy created for R77 and earlier, you will have to disable QoS acceleration to use other..."
We disabled the QoS blade and the issue disappeared. We are talking with TAC about it.
That definitely sounds like a bug 🙂
Sorry no ideas any more no much experience with QoS. TAC is indeed good step.
This is a longshot, only reason I paste it here it is very specific to SecureXL and FTP:
https://support.checkpoint.com/results/sk/sk168952
Also FTP without encryption? So no FTPS? What Jumbo take? No NAT or VPN in the connection?
Yes, this is FTP without encryption with not FTPS, they are running R81.10 JHF 83, there is no VPNs on this FW but there is NAT, in fact, we only have this issue when there is NAT on the FTP flow.
Hello, TAC found the cause of the issue: if you mark the QoS checkbox on the interface but only on Inbound (not in Outbound) then the FTP data connections are silently dropped.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 19 | |
| 14 | |
| 12 | |
| 12 | |
| 10 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY